2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1551 | MEDIUM | 6.1 | 0.7% | Feb 20, 2024 | Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the... |
| CVE-2024-1550 | MEDIUM | 6.1 | 0.6% | Feb 20, 2024 | A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user'... |
| CVE-2024-1549 | MEDIUM | 6.1 | 0.5% | Feb 20, 2024 | If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potenti... |
| CVE-2024-1548 | MEDIUM | 4.3 | 0.9% | Feb 20, 2024 | A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led ... |
| CVE-2024-1547 | MEDIUM | 6.5 | 0.7% | Feb 20, 2024 | Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another we... |
| CVE-2024-26267 | MEDIUM | 5.3 | 0.5% | Feb 20, 2024 | In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 befo... |
| CVE-2024-26265 | MEDIUM | 6.5 | 0.7% | Feb 20, 2024 | The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 ... |
| CVE-2024-25610 | MEDIUM | 5.4 | 0.5% | Feb 20, 2024 | In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 befor... |
| CVE-2024-1661 | MEDIUM | 5.5 | 0.3% | Feb 20, 2024 | A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerabi... |
| CVE-2024-25609 | MEDIUM | 6.1 | 0.4% | Feb 20, 2024 | HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 be... |
| CVE-2024-25608 | MEDIUM | 6.1 | 1.0% | Feb 20, 2024 | HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 be... |
| CVE-2024-25605 | MEDIUM | 5.3 | 0.5% | Feb 20, 2024 | The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 ... |
| CVE-2024-25604 | MEDIUM | 6.5 | 0.4% | Feb 20, 2024 | Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3,... |
| CVE-2024-25974 | MEDIUM | 5.4 | 0.5% | Feb 20, 2024 | The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload... |
| CVE-2024-25973 | MEDIUM | 5.4 | 0.6% | Feb 20, 2024 | The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker wit... |
| CVE-2024-25150 | MEDIUM | 4.3 | 0.4% | Feb 20, 2024 | Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported v... |
| CVE-2024-25149 | MEDIUM | 5.4 | 0.3% | Feb 20, 2024 | Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 befor... |
| CVE-2024-1559 | MEDIUM | 6.1 | 0.4% | Feb 20, 2024 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in ... |
| CVE-2024-1510 | MEDIUM | 5.4 | 0.5% | Feb 20, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-21890 | MEDIUM | 6.5 | 0.9% | Feb 20, 2024 | The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last charac... |
| CVE-2024-26129 | MEDIUM | 5.3 | 0.6% | Feb 19, 2024 | PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vu... |
| CVE-2024-25640 | MEDIUM | 5.4 | 0.3% | Feb 19, 2024 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. A sto... |
| CVE-2024-25634 | MEDIUM | 6.5 | 0.7% | Feb 19, 2024 | alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other... |
| CVE-2024-25983 | MEDIUM | 5.3 | 0.6% | Feb 19, 2024 | Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard ... |
| CVE-2024-25981 | MEDIUM | 5.3 | 0.6% | Feb 19, 2024 | Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now